15. Summary
15
OSI MODEL PDU Protocol Addressing
Network
Device
Application Data
HTTP, HTTPS, DNS,
SMTP, POP, FTP
Presentation
Session
Transport
Transport
Header
Data
TCP,UDP Port Number •Firewall
Segment
Network
Network
Header
Segment IP, IPX, Appletalk,
ICMP
IP Address
•Router
•Multi Layer
Switch (MLS)
Packet
Data Link
Frame
Header
Packet
Frame
Trailer 802.3, 802.11, PPP,
frame relay
MAC Address
•Switch
•Bridge
Frame
Physical Bit
•Hub
•Repeater
16. IPv4 Address
16
Stuktur IPv4
• Alamat IPv4 terdiri dari 32 bit
• Alamat IPv4 dibagi menjadi 4 oktet (8 bit) yang dipisahkan oleh dot
desimal.
• Alamat IPv4 terdiri dari dua bagian, yaitu bagian network dan
bagian host
21. IPv4 Address Classification
21
Blok alamat private adalah:
10.0.0.0 sampai 10.255.255.255 (10.0.0.0 /8)
172.16.0.0 sampai 172.31.255.255 (172.16.0.0 /12)
192.168.0.0 sampai 192.168.255.255 (192.168.0.0 /16)
22. IPv4 Address Classification
22
Alamat IP yang tidak dapat digunakan sebagai alamat Host:
• Alamat Network dan alamat Broadcast
• Alamat Default Route (0.0.0.0/8)
• Alamat Loopback (127.0.0.0/8)
• Local Link 169.254.0.0 s/d 169.254.255.255
23. Subnet Mask and Prefix Length
23
Prefix length adalah banyaknya bit pada alamat tersebut yang
merupakan alamat jaringan. Misalnya, dalam 172.16.4.0 /24, tanda
/24 adalah prefix length yang menunjukkan kepada kita bahwa 24 bit
pertama adalah alamat jaringan atau bagian alamat jaringan. Dan
sisa 8 bit atau oktet terakhir menujukan bagian dari host pada
jaringan tersebut.
24. IPv6
24
Do We Really Need a Larger Address Space ?
• Internet Users or PC
~530 million users in Q2 CY2002, ~945 million by 2004
(Source: Computer Industry Almanac)
Emerging population/geopolitical and Address space
• PDA, Pen-Tablet, Notepad,…
~20 millions in 2004
• Mobile phones
Already 1 billion mobile phones delivered by the industry
• Transportation
1 billion automobiles forecast for 2008
Internet access in Planes
• Consumer devices
Billions of Home and Industrial Appliances
29. Juniper Networks
29
• Started in 1997 by Silicon Valley engineers with VC
funding. Went public in 1999.
• Provides infrastructure solutions for service providers with
optically-enabled IP networks
• Revenues
Fiscal Year 1999: $102.6 million
First 6 months of 2000: $177 million
• One of the most successful technology IPOs in history.
Nasdaq:JNPR
• Market capitalization: ~ $42 billion
34. Junos OS Overview
34
A common language across Juniper’s routing, switching, and security
devices
Reduces complexity, increases availability, lowers TCO
36. Junos Software
36
Robust, modular operating system
• Provides industry-leading peformance and scalability
• Based on the FreeBSD UNIX operating system
• Each process runs in its own protected memory space, ensuring that
one process cannot directly interfere with another.
37. Single Software Train
37
A Single software train for all platform running JUNOS Software
• Ease management overhead by providing a consistent set of feature
that are implemented in a consistent manner
17.3
38. Separation of Control and Forwarding
38
All platform running JUNOS software share a common design goal:
• Clean separation of control and forwarding functions
17.3
39. Separation of Control and Forwarding
39
All platform running JUNOS software share a common design goal:
• Clean separation of control and forwarding functions
40. Routing Engine
40
Maintaining Routing Protocol and Forwarding Tables
Control and Monitors the Chasis
System management and User Access
Manage the FPE
41. Packet Forwarding Engine
41
Uses Layer 2 and Layer 3 forwading table, provided by RE, to forward
traffic toward its destinaton
Implements various service such as policing, stateless firewall filtering
and class of service
42. Transit Traffic Processing
42
Transit Traffic is forwarded through the local system
PFE uses the forwading table provided by RE
Example of transit include unicast and multicast
43. Exception Traffic Processing
43
Exception traffic is processed by local system (1)
Traffic destined for the local system is processed by RE CPU (exp:
Routing update, telnet session, ping, traceroute)
Traffic requiring the generation of ICMP message (exp: TTL expired)
Exception traffic is limit-rated rellated to protect from DOS (2)
1 2
44. Common User Inteface Options
44
Agenda : User Interface Options
o User Interface Options
The JUNOS Software CLI
CLI Basics
• Operational Mode
• Configuration Mode
52. Common User Inteface Options
52
Agenda : User Interface Options
o User Interface Options
The JUNOS Software CLI
• CLI Basics
Operational Mode
• Configuration Mode
55. Common User Inteface Options
55
Agenda : User Interface Options
o User Interface Options
The JUNOS Software CLI
• CLI Basics
• Operational Mode
Configuration Mode
72. Overview Junos Platform
72
SRX Series Services Gateways
The SRX Series services gateways provide up to 120 Gbps of
throughput. The SRX Series family is designed to meet the network and
security requirements for consolidated data centers, managed services
deployments, and aggregation of security services in both enterprise
and service provider environments.
Initial Configuration
Foryanto Jaya Wiguna
JNCIA
73. Initial Configuration
73
Agenda : Initial Configuration
Factory-Default Configuration
o Initial Configuration
o Interface Configuration
95. Overview Junos Platform
95
SRX Series Services Gateways
The SRX Series services gateways provide up to 120 Gbps of
throughput. The SRX Series family is designed to meet the network and
security requirements for consolidated data centers, managed services
deployments, and aggregation of security services in both enterprise
and service provider environments.
Secondary System Configuration
Foryanto Jaya Wiguna
JNCIA
119. Overview Junos Platform
119
SRX Series Services Gateways
The SRX Series services gateways provide up to 120 Gbps of
throughput. The SRX Series family is designed to meet the network and
security requirements for consolidated data centers, managed services
deployments, and aggregation of security services in both enterprise
and service provider environments.
Operational Monitoring and Maintenance
Foryanto Jaya Wiguna
JNCIA